PathToShip
PathToShip reviews the GitHub repository your builder syncs to and tells you what would break if you launched it. Built for apps made with Lovable, Bolt, v0, Replit, Cursor, Windsurf, Base44, Tempo, Firebase Studio or Claude, where the app works in the preview and nobody has checked what happens when strangers reach it. It finds the problems that actually take those apps down: API routes that never check who is calling, secrets on the client side of the boundary, Supabase tables created without Row Level Security, dependencies with known exploits, and the scalability and cost patterns that only hurt once you have users. You get a 0-100 readiness score across seven dimensions, a ship/not-ready verdict against a fixed bar, and the specific file and line for each finding. Ask for detail on any one and it explains the risk and the fix for your stack. Fix it, sync, and verify_fix re-scans and tells you what actually got resolved, what is still open, and what the fix newly introduced. Every tool is read-only. Source code is analysed in memory and never stored. Scanning a public repository needs no installation at all.
Details
https://pathtoship.com/api/mcp · streamable-http
